In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Cross-site Scripting (XSS) vulnerabilities in an interactive lesson.
Start learningUpgrade tinymce
to version 4.6.4 or higher.
tinymce
is a web based JavaScript HTML WYSIWYG editor control.
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) attacks, due to not encoding the base url passed into the iframe contents in the preview plugin.
<>